AIX7-00-003202 - The AIX operating system must be configured to use Multi Factor Authentication for remote connections.

Information

To assure accountability and prevent unauthenticated access, privileged and non-privileged users must utilize multifactor authentication to prevent potential misuse and compromise of the system.
Multifactor authentication uses two or more factors to achieve authentication.

Factors include:
1. Something you know (e.g., password/PIN);
2. Something you have (e.g., cryptographic identification device, token); and
3. Something you are (e.g., biometric).

The DoD CAC with DoD-approved PKI is an example of multifactor authentication.

Solution

Add or update the following lines in the /etc/pam.conf file:

sshd auth required pam_ckfile
sshd auth required pam_permission file=/etc/security/access.conffound=allow
sshd auth required pam_pmfa /etc/security/pmfa/pam_pmfa.conf

See Also

https://dl.dod.cyber.mil/wp-content/uploads/stigs/zip/U_IBM_AIX_7-x_V3R1_STIG.zip

Item Details

Category: CONFIGURATION MANAGEMENT

References: 800-53|CM-6b., CAT|II, CCI|CCI-000366, Rule-ID|SV-215438r991589_rule, STIG-ID|AIX7-00-003202, STIG-Legacy|SV-103033, STIG-Legacy|V-92945, Vuln-ID|V-215438

Plugin: Unix

Control ID: 9003a2f5752be9eb0ee3c704967cfae5772a25cccaea69cc15d2b2f898d3b158